Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Blogme | Drumster | 3.0 (including) | 3.0 (including) |